ie8 fix
Click Here

European ‘right-to-delete’ law: How enforceable is Facebook?

By | November 14, 2011, 3:42pm PST

Summary: New European law will require companies like Facebook to delete personal data if a user requests it. But amidst an Irish privacy audit, how compliant is, and will Facebook be?

Soon to-be-debated European law will offer European citizens’ the right to have their data deleted by third-party providers, including social networks like Facebook, Twitter and Google+.

But European member states, which will ultimately fulfil the law passed by the upcoming European Data Protection Directive, may not be able to guarantee that individuals’ personal data has in fact been deleted, a leading UK politician has said.

Taking a second to think through the various variables, contingencies, problems and reasoning, there is no logical way to regulate the major data hoarders of our time, including one high up on the European’s list: Facebook.


(Source: Flickr, CC)

Ed Vaizey, UK minister for culture, communications and creative industries, has warned that European law may be well in theory, but difficult to enforce at the local member state level.

In a speech, he said:

“[But] we also need to be clear about the practicalities of any regulation. For example, how do we enforce the ‘right to be forgotten’ when data can be copied and transferred across the globe in an instant? No Government can guarantee that photos shared with the world will be deleted by everyone when someone decides it’s time to forget that drunken night-out. We should not give people false expectations.”

Vaizey went on to criticise how the Directive could be used to “make firms outside of the EU subject to EU law”.

Last week, European Commissioner for Justice Viviane Reding said that individuals would have a right to force organisations to delete personal information and data about them, under the revised Directive, with a draft bill expected to go before European politicians in January.

Businesses and companies may not operate directly in Europe, but its users can be within the confines of the European zone.

Facebook, for example, only a few years ago had millions of European users but no physical presence in the continent. Feasibly, the European Commission, Europe’s upper house, could have imposed a fine to the California-based social networking giant, but there was no legislative measure in place to enforce the punishment if the company had no presence on European soil.

But that will change when the loophole is closed during the upcoming revision to the Data Protection Directive.

But in reality, only when a company holds a physical presence in the region can fines and punishments be imposed.

Since Facebook opening a datacenter in Dublin and an office in London, the social networking giant is at the forefront of European regulators minds. Not only did European Commissioner Viviane Reding tell The Register that Facebook had “nowhere to hide” over its data protection principles and morals, or lack thereof, but only recently the company was heavily rebuked by the European Parliament’s Privacy Platform last month by attendees and members of the panel.

Because Facebook does have a presence, along with Twitter, Microsoft, Google and Apple, all subsidiaries of their larger parent companies, this forces the parent corporation to abide by European law, as well as the law their headquarters is based.

This was one of the key premises behind the United States’ counter-terrorism law — the Patriot Act — accessing European citizens’ data and handing it back to their U.S.-based parent, thus making the data vulnerable to inspection by U.S. authorities and intelligence agencies. Gordon Frazer, managing director of Microsoft UK, admitted this exclusively to ZDNet earlier this year.

Having said that, there is no way to prove that data has not been deleted, unless a government or law enforcement agency — or each member states’ data protection agencies for that matter — inspect or audit each and every company to ensure compliance is met.

Facebook says that it “is compliant” with European data protection laws, as said in a statement to ZDNet. There is no surprise there, of course, as you would not expect for a minute for the statement to read: “Oh, whoops. You’re right; we weren’t compliant, not for a minute. Glad someone reminded us”.

But one thing does scream out at this current situation.

Facebook in California does not manage its European users; its subsidiaries in Ireland and London do, which makes Facebook liable ultimately under European law. That I think we have established.

But as Facebook is currently under the watchful eye of an Irish data protection privacy audit, in a bid to determine whether Facebook does in fact flout Irish and therefore European law, it could lead to massive and wide-scale consequences for the social networking giant.

If it goes against its word, Facebook is going to be not only in for a rocky few months, but it will be crucified by the European regulators. And, since Europe has the vast majority of its total user base, the social networking giant needs to pull its proverbial finger out, otherwise Facebook could see criminal charges thrown at it left, right and center.

Facebook’s downfall could be the modern day Enron. I say that with no melodrama, nor frankly with any remorse.

Related:

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Zack Whittaker, a criminologist who studied at the University of Kent, Canterbury, is a journalist, writer and broadcaster.

Disclosure

Zack Whittaker

I worked briefly with Microsoft UK in 2006 but no longer have any connection with the company. Regardless, I remain impartial and unbiased in my views.

I don't hold any stock or shares, investments or industrial secrets in any company, but have signed confidentiality agreements with a number of UK and U.S. organisations, whose names I am not at liberty to disclose.

I was involved with Kent Union, the University of Kent's student union, undertaking voluntary, non-salaried, elected positions between early 2009 and mid-2010.

No other company, body, government department, non-governmental organisation or third sector organisation employs me or pays me a salary in any capacity whatsoever.

As a freelance journalist, whenever expenses are given and taken by a company that is not CBS Interactive, these will be disclosed in each relevant post to ensure transparency.

I currently work with a UK law enforcement unit. Details of which are restricted, but this is an entirely separate position which bears no connection to other work.

(Updated: 23rd October 2011)

Biography

Zack Whittaker

Zack Whittaker, criminologist who studied at the University of Kent, UK, is a journalist, writer and broadcaster.

After studying criminology at university, though still in his early-20's, he has already had a series unconventional work and voluntary positions. He has worked with researchers studying neurological illnesses like Tourette's syndrome (which he suffers from), has given lectures on the nature of disabilities in the public community, and occasionally ends up speaking on television and radio discussing the events of the day.

He first had academic work published at the age of 22, then still an undergraduate, and has been cited by a wide range of publications: from the Huffington Post, Business Insider, AllThingsDigital, The Atlantic Wire and CBS News.

4
Comments

Join the conversation!

Just In

RE: European 'right-to-delete' law: How enforceable is Facebook?
Heenan73 15th Nov
@wright_is Thanks for that, but who's to know?
Do they mean "delete from view" or "remove from the system"?

I'd trust FB to remove it from view (I can check), but, personally, I wouldn't trust them not to keep it on file and sell it on.

And how can I possibly know?

I'm aware that Google sells me in aggregated form all over, and I really don't care; I know that adobe, M$ and others also aggregate data, but have remained below the 'politically correct' brigade's radar - and I really don't care.

But I don't want personal data sold, and I don't think I'll EVER trust FB, however often they tinker with details then attack others for their data control.

And, as I say, who's to know?
@Heenan73 The law "guarantees" European citizens the right to have their online data deleted (removed from the system), at their request.
@wright_is Thanks for that, but who's to know?
New European law will require companies like Facebook to delete personal data if a user requests it. But amidst an Irish privacy audit, how compliant is, and will Facebook be?

Not compliant at all which means Facebook will have to be sued again.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix